HP 8/20q HP StorageWorks 8/20q Fibre Channel Switch Command Line Interface Gui - Page 26

Applying IP security, Displaying IP security information, Policy and association information

Page 26 highlights

Applying IP security You can apply IP security to all communication between two systems, or to selected protocols, such as the Internet Control Message Protocol (ICMP), Transmission Control Protocol (TCP), or the User Datagram Protocol (UDP). Furthermore, instead of applying IP security, you can choose to discard all inbound or outbound traffic, or to allow all traffic without encryption. Both the AH and ESP security protocols provide source authentication, ensure data integrity, and protect against replay. IMPORTANT: IP security configurations can be complex: it is possible to unintentionally configure policies and associations that isolate a switch from all communication. If this happens, you can disable IP security by placing the switch in maintenance mode, and correct the problem through the serial port interface. For information about using maintenance mode and connecting through the serial port, see the HP StorageWorks 8/20q Fibre Channel Switch Installation and Reference Guide. Displaying IP security information You can display the security policy and security association databases sorted by the following parameters: • Active policies and associations; that is, policies and associations currently in use • Configured policies and associations; that is, policies and associations that have been saved in the database • Policies and associations that are being edited, but have not been saved You can display the following types of IP security configuration information: • Policy and association information, page 26 • IP security configuration history, page 27 • IP security configuration limits, page 27 Policy and association information To display general or specific policy and association information, enter the ipsec list command. The ipsec list command does not require an Admin session or an Ipsec Edit session. However, in an Ipsec Edit session, the ipsec association list and ipsec policy list commands display the same information. The following example displays all active policies and associations: 8/20q FC Switch #> ipsec list Active IPsec Information Security Association Database h2h-sh-sa h2h-hs-sa Security Policy Database h2h-hs-sp h2h-sh-sp Summary ------- Security Association Count: 2 Security Policy Count: 2 26 Network Configuration

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330

26
Network Configuration
Applying IP security
You can apply IP security to all communication between two systems, or to selected protocols, such as the
Internet Control Message Protocol (ICMP), Transmission Control Protocol (TCP), or the User Datagram
Protocol (UDP). Furthermore, instead of applying IP security, you can choose to discard all inbound or
outbound traffic, or to allow all traffic without encryption. Both the AH and ESP security protocols provide
source authentication, ensure data integrity, and protect against replay.
IMPORTANT:
IP security configurations can be complex: it is possible to unintentionally configure policies
and associations that isolate a switch from all communication. If this happens, you can disable IP security
by placing the switch in maintenance mode, and correct the problem through the serial port interface. For
information about using maintenance mode and connecting through the serial port, see the
HP
StorageWorks 8/20q Fibre Channel Switch Installation and Reference Guide
.
Displaying IP security information
You can display the security policy and security association databases sorted by the following parameters:
Active policies and associations; that is, policies and associations currently in use
Configured policies and associations; that is, policies and associations that have been saved in the
database
Policies and associations that are being edited, but have not been saved
You can display the following types of IP security configuration information:
Policy and association information
, page 26
IP security configuration history
, page 27
IP security configuration limits
, page 27
Policy and association information
To display general or specific policy and association information, enter the
ipsec list
command. The
ipsec list
command does not require an Admin session or an Ipsec Edit session. However, in an Ipsec
Edit session, the
ipsec association list
and
ipsec policy list
commands display the same
information.
The following example displays all active policies and associations:
8/20q FC Switch #> ipsec list
Active IPsec Information
Security Association Database
-----------------------------
h2h-sh-sa
h2h-hs-sa
Security Policy Database
------------------------
h2h-hs-sp
h2h-sh-sp
Summary
-------
Security Association Count:
2
Security Policy Count:
2